Control: tags -1 +upstream

Debian package python3-pam is incompatible with radicale. This is
considered an upstream issue of low importance: directly accessing PAM
is discouraged, safer methods exist, including a tested, packaged and
documented method via apache2 authnz-external module.

Quoting Borden (2026-03-14 03:08:08)
> 13 Mar 2026, 21:17 by [email protected]:
> 
> > As I wrote in my 1st reply, I will not get in the way of people
> > wanting to setup a lighter but also less secure system, so I will
> > not remove options. It seems I am therefore not convinced that 1)
> > is a good idea, but please do try be even more specific, if you
> > think that some concrete edits would be sensible without hiding
> > options for more adventurous users.
> >
> > Same for 2): Can you suggest concrete changes to the documentation?
> > That would help me reflect on whether I find that an improvement
> > over the existing texts, and something that I feel that I am ok
> > maintaining.
> >
> I'm unsure that I understand your question. Maybe we're working at
> different purposes. I believe that software (and everything, for that
> matter) should do what it's advertised to do. If Debian's radicale
> won't authenticate through PAM without patching, it shouldn't imply
> that it can. That was the point of my suggestions: it's OK to say No.

Debian radicale package does not imply that it works with PAM.

The contained code include functionality that is assumed fully
functional yet requires libraries not in Debian. That functionality is
not advertised as working in Debian, nor is upstream documentation
mangled to silence mentions of its existence: Dedicated Debian users
may choose to include an unofficial Python package with the needed
library, in which case that functionality becomes functional for them.

Since directly accessing PAM is not considered of high priority, the
added maintenance burden of including a package (either to adjust code
or to strip PAM-related documentation and/or code) is *not* acceptable.


> If users want to patch radicale to authenticate over plain text or
> black magic, they can. Upstream has instructions on how to install
> through pip and git. It seems easier and safer to maintain patches
> against source than against Debian's updates.

Users wanting to not use Debian-packaged radicale but instead use pip
are welcome to do so, but such bypassing of Debian packages is
irrelevant to track as an issue for this package.

Yes, patches against source is indeed better, and I encourage
contributing patches against upstream source to gain support for the
PAM module provided in Debian.


> Directing determined users to upstream seems far less aggravating to
> fielding complaints and bug reports. At least for me it is.

Agreed. Which is what this bugreport is currently doing: Directing
determined users to upstream - upstream needs to be nudged to accept
the patch (or something functionally similar that covers multiple PAM
implementations) for this bugreport to be considered resolved, and
until then the Debian package documentation references this bugreport
when talking about (still generally discouraged) direct PAM acces.

In short: Please engage upstream to have them enable support for the
PAM module in Debian, e.g. using the patch attached to this bugreport.


 - Jonas

-- 
 * Jonas Smedegaard - idealist & Internet-arkitekt
 * Tlf.: +45 40843136  Website: http://dr.jones.dk/
 * Sponsorship: https://ko-fi.com/drjones

 [x] quote me freely  [ ] ask before reusing  [ ] keep private

Attachment: signature.asc
Description: signature

Reply via email to